oss-sec mailing list archives

Re: PostgreSQL insecure install via yum (multiple problems)


From: "Eric H. Christensen" <echriste () redhat com>
Date: Mon, 19 Aug 2013 21:19:41 -0400

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On Mon, Aug 19, 2013 at 06:58:22PM -0600, Kurt Seifried wrote:
Signing RPM's isn't very useful if you never make the signing key
available!

You mean like this:  http://keys.fedoraproject.org/pks/lookup?search=0x442df0f8&op=vindex

I'm pretty sure pgp.mit.edu isn't the best source for PGP keys any longer, unfortunately.

- -- Eric

- --------------------------------------------------
Eric "Sparks" Christensen
Red Hat, Inc - Product Security Team

sparks () redhat com - sparks () fedoraproject org
097C 82C3 52DF C64A 50C2  E3A3 8076 ABDE 024B B3D1
- --------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)

iQGcBAEBCgAGBQJSEsQqAAoJEB/kgVGp2CYvhFAL/3vUyx8NgCyik42NiJKqOlAe
yarq7tz6r3CoIxNkcl6LkOpNfsNK6/eSs3K5/ZngUXJX0fIW+jISAPU8TSKLY9AG
nkEMAJnMpDwwzLbOjrOpSJglFsb4pj+A/q3WTD09HvocJqZXyYKbQK3li5nsj6qR
TVlBYchjKs3yRBZQdobwK7YVkyQrZIB8a7bFZhyH5OUKHOsWh6cae/7bpkJ55kX/
8n0j+OP1rAMhPXior40soJAmG/XrVQsiuw4GAJ8eGoc1bGybcBZ5SarRTrbq2s7q
DQaQZn9HfwCeXoHODYyJj6Pp77l9qKKB72BF+2BDDLmI8lsI681xmMW3On7rCoP6
PbLkxUHWicO9KtyNg1WYW8wHv0HiwnLPhNNilzlNLoTBBGRIZr6Bb0+Nq1uD1uUD
E4GymQfIyYRNvowyyFGlh/2fMY5tpFMSR6gtu50tZpaSyhKS0bjzYM68jRX6YCW8
YyOhcL7uKKenZESWcPHTgq8Z/Yd4rJs0zRrKlXVzsA==
=Y/N1
-----END PGP SIGNATURE-----


Current thread: